CRITICAL
UTT HiPER 1250GW HTTP aspApBasicConfigUrcp strcpy stack-based overflow
Published Aug 19, 2026
9.4
CRITICALCVSS 4.0
EPSS 0.79%
Description
A security vulnerability has been detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this vulnerability is the function strcpy of the file /goform/aspApBasicConfigUrcp of the component HTTP Handler. The manipulation of the argument pvid leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.
Affected products
-
- Version 3.2.7-210907-180535StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| UTT | HiPER 1250GW | n/a |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-62223 Advisory
- https://github.com/7wkajk/CVE-VUL/blob/main/106.md exploit
- https://vuldb.com/cve/CVE-2026-76004 third-party-advisory
- https://vuldb.com/submit/877885 third-party-advisory
- https://vuldb.com/vuln/391920 vdb-entrytechnical-description
- https://vuldb.com/vuln/391920/cti signaturepermissions-required
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-62223 | Advisory | |
| https://github.com/7wkajk/CVE-VUL/blob/main/106.md | exploit | |
| https://vuldb.com/cve/CVE-2026-76004 | third-party-advisory | |
| https://vuldb.com/submit/877885 | third-party-advisory | |
| https://vuldb.com/vuln/391920 | vdb-entrytechnical-description | |
| https://vuldb.com/vuln/391920/cti | signaturepermissions-required |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Aug 19, 2026
Updated Aug 19, 2026
Reserved Aug 18, 2026
Link CVE-2026-76004
CISA Vulnrichment
Updated Aug 19, 2026
ENISA EUVD
EUVD-2026-62223 Assigner VulDB
Published Aug 19, 2026
Updated Aug 19, 2026
Exploited since n/a
Link EUVD-2026-62223